Live data from Hacker News

A Message to Our Customers

apple.com

921–930 of 1001 posts

Re: A Message to Our Customers

#921
I feel like Apple is intentionally over simplifying it for the purpose of this letter or maybe to push back on the FBI ask more easily.

Apple could propose to secure access to the FBI using the same level of security that it uses to protect the access to the phone content for the owner of the phone himself. Tim Cook only talks about one solution of a "tool" that it could install.

If the same level (and method) of security is used then saying that there is a risk of the backdoor being hacked would be equivalent to saying that there is a similar risk of the user access being hacked.

Re: A Message to Our Customers

#922
post #540

Earlier quoted context omitted.

I'm not sure you can draw the conclusion that Apple can push OS updates to a locked phone. What Tim Cook wrote is that > "install it on an iPhone recovered during the investigation." > "the potential to unlock any iPhone in someone’s physical possession." So the FBI has the physical phone already. They can deliver to Apple who can disassemble it and either use a JTAG/Flash programmer on an internal connector to manua…

"I'm not sure you can draw the conclusion that Apple can push OS updates to a locked phone." The iphone contains a sim card. A sim card is a complete, general purpose computer with its own CPU and RAM and the ability to run arbitrary java programs that can be uploaded, without your knowledge by your carrier. You are owned . Deeply, profoundly, in ways that you have no way to manage/mitigate. The real question, for me…

A sim card gets to send messages to the baseband in response to requests from the baseband. It doesn't have arbitrary memory access unless the baseband has really nasty bugs.

Re: A Message to Our Customers

#923

Earlier quoted context omitted.

> I mean, let's get real for a second. The toolchain already exists. Apple has the source code, hardware simulators, debugging harnesses, and the original engineers. There's no magic. As long as those things exist, the danger of a hack getting public is real, especially if the source for iOS is ever stolen, or one of the core engineers goes rogue. If Apple's own internal security can't keep a more polished tool under…

No, I'm saying Apple shouldn't hand over their encryption keys. I'm saying the FBI should hand over the iPhone, and Apple hands back the files, but doesn't give them any hacked phone. In a paperless world, and unbreakable encryption, what is the point of warrants or regulations at all? If a company that say, committed crimes, financial or criminal, has a warrant served on them, what if the response is, "Hey, we'd lov…

>If a company that say, committed crimes, financial or criminal, has a warrant served on them, what if the response is, "Hey, we'd love to give you our emails, but all employees use end to end encryption, and every desktop has unbreakable filesystem crypto, and our IT department can't unlock anything, so you must compel the users to hand over keys?"

Are you an American or Foreign? In the American constitution, the 5th amendment, legally protects a party from being forced to incriminate one self. So if you are still alive, and slapped with a warrant, your rights protect you from giving up your private key.

Re: A Message to Our Customers

#924
post #896

Earlier quoted context omitted.

Interestingly, if you accept that code can be copyrighted, and that only things that are expressions (speech) are eligible for copyright ("A copyrighted work must be an original work of authorship which is fixed in a tangible medium of expression"), then code == speech. So, by compelling Apple to code something that doesn't exist, the government would indeed actually be compelling speech.

Court processes involve compelled speech all the time. Heck, compelling witness testimony, which is one of the most well-established parts of the court process, is nothing but compelling speech. So, I'm not sure what the value is of a clever argument that compelling Apple to comply with the order here is "compelling speech" is supposed to be (likewise, the upthread one about NSL canaries.)

Fair points that I concede. I'll note I also forgot the nuance mentioned by morsch (that a canary is compelling a lie, which is potentially different).

On a separate note though, I've always thought it would be interesting to see a member of Congress be issued a NSL and then have them read it on the floor of the House/Senate (since they have parliamentary immunity for anything they say on the floor of the House or Senate).

Re: A Message to Our Customers

#925
post #861

Earlier quoted context omitted.

Save people like me a trip to the Google: NSL = A national security letter (NSL) is an administrative subpoena issued by the United States federal government to gather information for national security purposes. NSLs do not require prior approval from a judge.

Not only do NSLs not require approval from a judge, they also include a very intimidating gag order that prevents you from discussing the issue with anyone else (including even your own family). One of the big problems with NSLs is that you can't let anyone know that you've received or acted on one, so there's very little accountability. Hence the recent trend of some companies including a warrant canary on their web…

That's not how canaries work. You don't delete them, you fail to update them.

Re: A Message to Our Customers

#926
It is worth pointing out one salient fact: the phone in question did not belong to the shooter, it belonged to the shooter's employer, which in this case is the county government. That makes Apple's position much less tenable because the owner of the phone is (presumably) consenting to -- maybe even actively encouraging -- the recovery of the data.

Re: A Message to Our Customers

#928
post #2

Huge props to Apple - here's hoping against hope that Google, Facebook, and Amazon get behind this. One thing I was wondering is how Apple is even able to create a backdoor. It is explained toward the end: "The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force…

"...and disabled Touch ID - which is hackable with a bit of effort to get your fingerprint." As long as we're on the topic of encryption, phones, and law enforcement it's worth keeping in mind that in the US at least courts can compel you to unlock your phone with Touch ID, even though they can't compel you to give them a password. Communicating a password is considered speech, so self-incriminating speech is protect…

When entering any questionable law enforcement situation (TSA, walking near a protest, traveling internationally) I always switch my phone to not use TouchID. Say what you will.

Re: A Message to Our Customers

#929
post #826

Earlier quoted context omitted.

> Bringing a bunch of special agents along with you to a meeting is intimidating Again, what is intimidating about that? The agency they were dealing with was the FBI, right? And that's the correct agency to deal with this matter, right? Well in the FBI, 'special agent' simply means any worker who does investigatory work.

The way powerful people often maintain control of a situation is through contrivances such as unusual dress, unusual ways of speaking, unusual rituals or by having a large entourage. If you analyse each element closely it's clear that they're silly. Why do they need earpieces in when visiting Apple? Why must all the cars match? Why must they dress in the same way? Why do they need to bring all those people, what are…

Earpieces are probably worn routinely, just as many other people you may see walking around.

Large organizations typically procure fleets of vehicles that are all the same model. This reduces development and maintenance costs.

Many institutions, particularly law enforcement, have strict dress regulations and many distribute their own uniforms appropriate to the particular position.

Re: A Message to Our Customers

#930

Earlier quoted context omitted.

"To be fair - the only reason he's doing it is because it would cause a significant drop in sales for Apple devices." That's not being fair at all. To say the only reason he is doing it is to protect iPhone sales doesn't speak to Tim's character. Of course he cares about sales, but he also cares about privacy.

Tim answers to shareholders. Shareholders look at the bottom line and not his character.

Shareholders, which includes Tim Cook, all get to choose what they care about. Humans have complex motivations.
Post reply on HN